CVE-2020-37037: AVAST SecureLine 5.5.522.0 - 'SecureLine' Unquoted Service Path
Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37037?
CVE-2020-37037 has a medium severity rating due to its potential to allow local users to execute code with elevated privileges.
How do I fix CVE-2020-37037?
To fix CVE-2020-37037, update Avast SecureLine to the latest version to address the unquoted service path vulnerability.
Who is affected by CVE-2020-37037?
Users of Avast SecureLine version 5.5.522.0 are affected by CVE-2020-37037 due to its unquoted service path issue.
Can CVE-2020-37037 be exploited remotely?
No, CVE-2020-37037 is a local vulnerability that requires local access to exploit.
What type of vulnerability is CVE-2020-37037?
CVE-2020-37037 is classified as an unquoted service path vulnerability which can lead to privilege escalation.